A Background Check Is Only as Reliable as the Identity Behind It

The candidate speaking to you through a screen has a strong resume. Their identity appears genuine, their face matches their photograph, and the interview is going well. They know the details an employer would expect and can answer questions about their career, qualifications, and previous roles. They look like the ideal candidate. Until you discover they do not exist. It may sound like something from a 90s spy thriller, but it is now one of the most serious security threats facing businesses, and generative AI is making it easier.
A 2025 Gartner survey of 3,000 job candidates found that 6% admitted to interview fraud, either posing as someone else or having another person interview on their behalf. By 2028, Gartner predicts that one in four candidate profiles worldwide will be fake, largely driven by new AI tools. But the problem works both ways. Businesses are also increasing their use of AI to screen candidates. The same survey found that just 26% of applicants trust AI to evaluate them fairly, while 25% immediately lose trust in a potential employer when they learn that AI is part of the recruitment process. AI is creating mistrust on both sides, with businesses and candidates increasingly trying to use technology to stay one step ahead of each other.
Behind this is a more serious and organized form of fraud. Generative AI allows criminals to build a convincing person piece by piece: gathering someone’s personal history online, manufacturing documents to support it, cloning their voice, and animating their face from a handful of photographs. Unlike the Gartner example above, the aim is not simply to get through an application process and secure a job. It is to gain access to trusted systems, data, and intellectual property that can be used for leverage or profit, while also collecting a salary. Some sophisticated criminals develop their own tools and change their methods as soon as defenses catch up. Others can buy what they need online and arrive at an interview using an identity that appears every bit as real as the person on the other side of the screen.
Last year, the U.S. Department of Justice revealed that overseas workers had allegedly compromised the identities of more than 80 Americans to obtain remote jobs at over 100 US companies, including several Fortune 500 businesses. The scheme caused at least $3 million in legal fees, network remediation costs, and other losses. A background check may accurately confirm the history linked to a particular name, but it cannot establish that the person on screen is entitled to use that identity. If an impostor has borrowed a real person’s information, or constructed a synthetic identity using both genuine and fabricated details, a business can perform all the right checks on the wrong person. Before asking whether someone’s history makes them suitable for a role, employers need to be confident that the person applying, interviewing, and ultimately joining the organization is who they claim to be.
Identity Must Be Established Before History Can Be Trusted
The practical answer is to put identity verification at the start of the hiring process and connect it to the checks that follow. An applicant can capture an identity document and provide a live facial image, allowing biometric technology to compare the person with the photograph on the document. The document should also be checked for signs of tampering or fabrication, while its information can be verified against trusted data sources where appropriate. This binds the person, the document, and the identity being submitted for screening.
That link must continue throughout the hiring journey. The person who submits the application, completes an assessment, attends the interview, and arrives on their first day should be the same person. Verifying identity at only one point leaves gaps. Employers should be able to re-establish trust at important moments, particularly before issuing equipment, activating credentials, granting access to sensitive systems, or approving changes to an employee’s identity or payment details.
A Selfie Alone Is No Longer Enough
Comparing two faces only helps if the camera is seeing a genuine person. A fraudster could hold up a photograph, replay a recorded video, wear a mask, or present a synthetic face directly to the camera. Presentation attack detection is designed to identify attacks made in front of the sensor, including printed images, screens, and masks. Injection attack detection addresses a different problem: digital content inserted into the capture process, such as manipulated or AI-generated imagery that bypasses the camera entirely.
These protections have to work together. Even a highly accurate facial comparison system could confidently match two versions of the same deepfake if it cannot establish that the image is live, genuine, and captured through the expected channel. Asking an applicant to perform an unusual movement during an interview may expose a poor-quality fake, but it is not a reliable defense. Criminals adapt quickly, which is why organizations need multiple layers of protection rather than relying on any single check.
Build Trust Without Treating Every Candidate Like a Criminal
Stronger verification still needs to be proportionate to the role and the risk. Someone joining remotely with access to source code, financial systems, personal data, or critical infrastructure may require a higher level of assurance than a candidate applying for a low-risk, in-person role. A risk-based process can introduce stronger checks where the potential consequences are greater, while keeping the experience straightforward for genuine candidates.
Employers should also explain what information they collect, why they need it, how it will be protected, and how long it will be retained. As Gartner notes, candidates already worry that AI could judge them unfairly. Verification that feels secretive or unnecessarily intrusive will only increase that mistrust. Clear communication matters, as does a route to human review when an automated check fails or returns an uncertain result.
Remote hiring has allowed organizations to recruit talent from almost anywhere, and that opportunity is too valuable to give up. But trust can no longer depend on whether a candidate looks convincing on a video call. A background check can tell an employer a great deal about someone’s history. The first step is to prove whose history it is.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!




